Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves two vulnerabilities can now be installed.. # Security update for ucode-intel Announcement ID: SUSE-SU-2026:0668-1 Release Date: 2026-02-26T15:21:26Z Rating: important References: * bsc#1229129 * bsc#1258046 Cross-References: * CVE-2024-24853 * CVE-2025-31648 CVSS scores: * CVE-2024-24853 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-24853 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2025-31648 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N * CVE-2025-31648 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 *SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260210 release (bsc#1258046) * CVE-2024-24853: Updated fix for incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2025-31648: Improper handling of values in the microcode flow for some Intel Processor Family may allow an escalation of privilege. (bsc#1258046) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 *SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-668=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-668=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * openSUSE Leap 15.6 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux EnterpriseMicro 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260210-150200.62.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260210-150200.62.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24853.html * https://www.suse.com/security/cve/CVE-2025-31648.html * https://bugzilla.suse.com/show_bug.cgi?id=1229129 * https://bugzilla.suse.com/show_bug.cgi?id=1258046 . An important security update for openSUSE resolves critical issues in ucode-intel that could escalate user privileges.. openSUSE, ucode-intel, important update, escalation of privilege. . Severity: Important. LinuxSecurity.com Team
* bsc#1206418 * bsc#1211382 * bsc#1214099 * bsc#1215278 * bsc#1221323 . # Security update for microcode_ctl Announcement ID: SUSE-SU-2025:1032-1 Release Date: 2025-03-26T14:22:25Z Rating: important References: * bsc#1206418 * bsc#1211382 * bsc#1214099 * bsc#1215278 * bsc#1221323 * bsc#1224277 * bsc#1229129 * bsc#1230400 * bsc#1233313 * bsc#1237096 Cross-References: * CVE-2022-40982 * CVE-2022-41804 * CVE-2023-22655 * CVE-2023-23583 * CVE-2023-23908 * CVE-2023-28746 * CVE-2023-38575 * CVE-2023-39368 * CVE-2023-42667 * CVE-2023-43490 * CVE-2023-45733 * CVE-2023-45745 * CVE-2023-46103 * CVE-2023-47855 * CVE-2023-49141 * CVE-2024-21820 * CVE-2024-21853 * CVE-2024-23918 * CVE-2024-23984 * CVE-2024-24853 * CVE-2024-24968 * CVE-2024-24980 * CVE-2024-25939 * CVE-2024-31068 * CVE-2024-36293 * CVE-2024-37020 * CVE-2024-39355 CVSS scores: * CVE-2022-40982 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-40982 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2022-41804 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:H * CVE-2022-41804 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:H * CVE-2023-22655 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N * CVE-2023-23583 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-23583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-23583 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-23908 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2023-23908 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2023-38575 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-39368 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42667 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-42667 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-43490 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2023-45733 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2023-45745 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2023-46103 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-47855 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-49141 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-49141 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49141 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2023-49141 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2024-21820 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2024-21820 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2024-21820 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-21820 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2024-21853 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-21853 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-21853 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-21853 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-23918 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-23918 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2024-23918 ( NVD ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-23918 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2024-23984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2024-23984 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-23984 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-23984 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-24853 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-24853 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2024-24968 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-24968 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-24968 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-24968 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-24980 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2024-24980 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N * CVE-2024-25939 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-25939 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-31068 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-31068 ( SUSE): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-31068 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-31068 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-36293 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-36293 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2024-36293 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-36293 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2024-37020 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-37020 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L * CVE-2024-37020 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-37020 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L * CVE-2024-37020 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L * CVE-2024-39355 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-39355 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2024-39355 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-39355 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves 27 vulnerabilities can now be installed. ##Description: This update for microcode_ctl fixes the following issues: * CVE-2024-31068: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel Processors may allow privileged user to potentially enable denial of service via local access. (bsc#1237096) * CVE-2024-36293: A potential security vulnerability in some Intel Software Guard Extensions (Intel SGX) Platforms may allow denial of service. Intel is releasing microcode updates to mitigate this potential vulnerability. (bsc#1237096) * CVE-2024-39355: A potential security vulnerability in some 13th and 14th Generation Intel Core Processors may allow denial of service. Intel is releasing microcode and UEFI reference code updates to mitigate this potential vulnerability. (bsc#1237096) * CVE-2024-37020: A potential security vulnerability in the Intel Data Streaming Accelerator (Intel DSA) for some Intel Xeon Processors may allow denial of service. Intel is releasing software updates to mitigate this potential vulnerability. (bsc#1237096) * CVE-2024-21853: Faulty finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel Xeon Processors may allow an authorized user to potentially enable denial of service via local access. (bsc#1233313) * CVE-2024-23918: Improper conditions check in some Intel Xeon processor memory controller configurations when using Intel SGX may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1233313) * CVE-2024-21820: Incorrect default permissions in some Intel Xeon processor memory controller configurations when using Intel SGX may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1233313) * CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel Processors may allow an privileged user to potentially enable a denial of service via local access. (bsc#1230400) * CVE-2024-23984:Observable discrepancy in RAPL interface for some Intel Processors may allow a privileged user to potentially enable information disclosure via local access. (bsc#1230400) * CVE-2024-24853: Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2024-25939: Mirrored regions with different values in 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access. (bsc#1229129) * CVE-2024-24980: Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2023-42667: Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2023-49141: Improper isolation in some Intel(R) Processors stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2023-45733: Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access. (bsc#1224277) * CVE-2023-46103: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access. (bsc#1224277) * CVE-2023-45745: Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1224277) * CVE-2023-47855: Improper input validation in someIntel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1224277) * CVE-2023-39368: Protection mechanism failure of bus lock regulator for some Intel Processors may allow an unauthenticated user to potentially enable denial of service via network access. (bsc#1221323) * CVE-2023-38575: Non-transparent sharing of return predictor targets between contexts in some Intel Processors may allow an authorized user to potentially enable information disclosure via local access. (bsc#1221323) * CVE-2023-28746: Information exposure through microarchitectural state after transient execution from some register files for some Intel Atom Processors may allow an authenticated user to potentially enable information disclosure via local access. (bsc#1221323) * CVE-2023-22655: Protection mechanism failure in some 3rd and 4th Generation Intel Xeon Processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1221323) * CVE-2023-43490: Incorrect calculation in microcode keying mechanism for some Intel Xeon D Processors with Intel SGX may allow a privileged user to potentially enable information disclosure via local access. (bsc#1221323) * CVE-2023-23583: Fixed potential CPU deadlocks or privilege escalation (bsc#1215278) * CVE-2022-40982: Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (bsc#1206418) * CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access. * CVE-2022-41804: Unauthorized error injection in Intel(R) SGX or Intel(R) TDX forsome Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. Other fixes: * Intel CPU Microcode was updated to the 20250211 release (bsc#1237096) * Security updates for INTEL-SA-01166 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01166.html * Security updates for INTEL-SA-01213 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01213.html * Security updates for INTEL-SA-01139 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01139.html * Security updates for INTEL-SA-01228 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01228.html * Security updates for INTEL-SA-01194 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01194.html * Update for functional issues. Refer to Intel Core Ultra Processor for details. * Update forfunctional issues. Refer to 13th/14th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 8th and 9th Generation Intel Core Processor Family Spec Update for details. * Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update https://cdrdv2-public.intel.com/637780/637780_3rd_Gen_Xeon_Scalable_Spec_Update_024US.pdf for details. * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Update https://cdrdv2-public.intel.com/709192/709192_Intel%C2%AE%20Xeon%C2%AE%20E-2300%20Processor%20Family%20Specification%20Update_Rev004US.pdf for details. * Update for functional issues. Refer to Intel Xeon 6700-Series Processor Specification Update for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series https://cdrdv2-public.intel.com/764616/764616_004.pdf for details * Intel CPU Microcode was updated to the 20241112 release (bsc#1233313) * Security updates for INTEL-SA-01101. * Security updates for INTEL-SA-01079. * Security updates for INTEL-SA-01079. * Updated security updates for INTEL-SA-01097. * Updated security updates for INTEL-SA-01103. * Update for functional issues. Refer to Intel Core Ultra Processor for details. * Update for functional issues. Refer to 14th/13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update for details. * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon D-1700 and D-1800 Processor Family Specification Update for details * Intel CPU Microcode was updated to the 20241029 release (bsc#1230400) * Update for functional issues. Refer to 14th/13th Generation Intel Core Processor Specification Update for details. * Intel CPU Microcode was updated to the 20240910 release (bsc#1230400) * Security updates for INTEL-SA-01103 * Security updates for INTEL-SA-01097 * Update for functional issues. Refer to Intel Core Ultra Processor for details. * Update for functional issues. Refer to 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series for details. * Intel CPU Microcode was updated to the 20240813 release (bsc#1229129) * Security updates for INTEL-SA-01083 * Security updates for INTEL-SA-01118 * Security updates for INTEL-SA-01100 * Security updates for INTEL-SA-01038 * Security updates for INTEL-SA-01046 * Update for functional issues. Refer to Intel Core Ultra Processor for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update for details. * Update for functionalissues. Refer to 3rd Generation Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 2nd Generation Intel Xeon Processor Scalable Family Specification Update for details * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Update for details. * Update for functional issues. Refer to 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 10th Gen Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 10th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 8th and 9th Generation Intel Core Processor Family Spec Update for details. * Update for functional issues. Refer to 8th Generation Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 7th and 8th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series for details. * Update for functional issues. Refer to Intel Atom x6000E Series, and Intel Pentium and Celeron N and J Series Processors for Internet of Things (IoT) Applications for details. * Intel CPU Microcode was updated to 20240531 release: * Update for functional issues. Refer to Intel Pentium Silver and Intel Celeron Processor Specification Update * Intel CPU Microcode was updated to the 20240514 release (bsc#1224277) * Security updates for INTEL-SA-01051 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01051.html * Security updates for INTEL-SA-01052 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01052.html * Security updates for INTEL-SA-01036 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01036.html * Update for functional issues. Refer to 5th Gen Intel Xeon Processor Scalable Family for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 14th 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series https://cdrdv2-public.intel.com/764616/764616_004.pdf for details. * * Intel CPU Microcode was updated to 20240312 release. (bsc#1221323) * Security updates for INTEL-SA-INTEL-SA-00972 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-00972.html *Security updates for INTEL-SA-INTEL-SA-00982 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-00982.html * Security updates for INTEL-SA-INTEL-SA-00898 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-00898.html * Security updates for INTEL-SA-INTEL-SA-00960 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-00960.html * Security updates for INTEL-SA-INTEL-SA-01045 https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref= sa-01045.html * Update for functional issues. Refer to Intel Core Ultra Processor for details. * Update for functional issues. Refer to 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 10th Gen Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 10th Generation Intel Core Processor Specification Update https://cdrdv2-public.intel.com/615213/615213_013.pdf for details. * Update for functional issues. Refer to 8th and 9th Generation Intel Core Processor Family Spec Update for details. * Update for functional issues. Refer to 8th Generation Intel Core Processor Families Specification Update https://cdrdv2-public.intel.com/338025/338025_007.pdf for details. * Update for functional issues. Refer to 7th and 8th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Scalable Processors Specification Update https://cdrdv2-public.intel.com/634897/634897_3rd%20Generation%20Intel%20Xeon%20Scalable%20Processors%20codename%20Cooper%20Lake%20Specification%20Update_Rev015US.pdf for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update https://cdrdv2-public.intel.com/637780/637780_3rd_Gen_Xeon_Scalable_Spec_Update_024US.pdf for details. * Update for functional issues. Refer to 2nd Generation Intel Xeon Processor Scalable Family Specification Update https://cdrdv2-public.intel.com/338848/338848_2nd%20Gen%20Intel%C2%AE%20Xeon%C2%AE%20Scalable%20Processors%20Specification%20Update_Rev028US.pdf for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series https://cdrdv2-public.intel.com/764616/764616_004.pdf for details. * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Updatehttps://cdrdv2-public.intel.com/709192/709192_Intel%C2%AE%20Xeon%C2%AE%20E-2300%20Processor%20Family%20Specification%20Update_Rev004US.pdf for details. * Update for functional issues. Refer to Intel Xeon Processor Scalable Family Specification Update https://cdrdv2-public.intel.com/613537/613537_Intel%C2%AE%20Xeon%C2%AE%20Processor%20Scalable%20Family%20Specification%20Update_Rev033US.pdf for details. * Update for functional issues. Refer to Intel Atom C3000 Processor Product Family Specification Update https://cdrdv2-public.intel.com/336345/336345_C3000_SU_Rev022.pdf for details. * Update for functional issues. Refer to Intel Atom x6000E Series, and Intel Pentium and Celeron N and J Series Processors for Internet of Things (IoT) Applications https://cdrdv2-public.intel.com/636674/636674_Intel_Atom_Pentium_Celeron_Public_SpecUpdate_rev2p2.pdf for details. * Update for functional issues. Refer to Intel Pentium Silver and Intel Celeron Processor Specification Update https://cdrdv2-public.intel.com/336562/336562_Intel%C2%AE%20Pentium%C2%AE%20Silver%20and%20Intel%C2%AE%20Celeron%C2%AE%20Processors%20_rev007.pdf for details. * Update for functional issues. Refer to Intel Pentium Silver and Intel Celeron Processor Specification Update https://cdrdv2-public.intel.com/634542/634542-001.pdf for details. * Intel CPU Microcode was updated to 20231114 release. (bsc#1215278) * Security updates for INTEL-SA-00950 * Update for functional issues. Refer to 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 10th Gen Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update fordetails. * Update for functional issues. Refer to 3rd Generation Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series for details. * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Update for details. * Intel CPU Microcode was updated to 20231114 pre-release (labeled 20231113). (bsc#1215278) * Intel CPU Microcode was updated to 20230808 release. (bsc#1214099) * Security updates for INTEL-SA-00828 (bsc#1206418) * Security updates for INTEL-SA-00836 * Security updates for INTEL-SA-00837 * Update for functional issues. Refer to 13th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 12th Generation Intel Core Processor Family for details. * Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update for details. * Update for functional issues. Refer to 10th Gen Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 8th and 9th Generation Intel Core Processor Family Spec Update for details. * Update for functional issues. Refer to 8th Generation Intel Core Processor Families Specification Update for details. * Update for functional issues. Refer to 7th and 8th Generation Intel Core Processor Specification Update for details. * Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series for details. * Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Scalable Processors Specification Update for details. * Update for functional issues. Refer to 2nd Generation Intel Xeon Processor Scalable FamilySpecification Update for details. * Update for functional issues. Refer to Intel Xeon Processor Scalable Family Specification Update for details. * Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update for details. * Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details. * Update for functional issues. Refer to Intel Xeon D-2100 Processor Specification Update for details. * Intel CPU Microcode was updated to 20230613 release. * Intel CPU Microcode was updated to 20230512 release. * Intel CPU Microcode was updated to 20230512 release. (bsc#1211382) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2025-1032=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2025-1032=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * microcode_ctl-1.17-102.83.81.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * microcode_ctl-1.17-102.83.81.1 ## References: * https://www.suse.com/security/cve/CVE-2022-40982.html * https://www.suse.com/security/cve/CVE-2022-41804.html * https://www.suse.com/security/cve/CVE-2023-22655.html * https://www.suse.com/security/cve/CVE-2023-23583.html * https://www.suse.com/security/cve/CVE-2023-23908.html * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2023-38575.html * https://www.suse.com/security/cve/CVE-2023-39368.html * https://www.suse.com/security/cve/CVE-2023-42667.html *https://www.suse.com/security/cve/CVE-2023-43490.html * https://www.suse.com/security/cve/CVE-2023-45733.html * https://www.suse.com/security/cve/CVE-2023-45745.html * https://www.suse.com/security/cve/CVE-2023-46103.html * https://www.suse.com/security/cve/CVE-2023-47855.html * https://www.suse.com/security/cve/CVE-2023-49141.html * https://www.suse.com/security/cve/CVE-2024-21820.html * https://www.suse.com/security/cve/CVE-2024-21853.html * https://www.suse.com/security/cve/CVE-2024-23918.html * https://www.suse.com/security/cve/CVE-2024-23984.html * https://www.suse.com/security/cve/CVE-2024-24853.html * https://www.suse.com/security/cve/CVE-2024-24968.html * https://www.suse.com/security/cve/CVE-2024-24980.html * https://www.suse.com/security/cve/CVE-2024-25939.html * https://www.suse.com/security/cve/CVE-2024-31068.html * https://www.suse.com/security/cve/CVE-2024-36293.html * https://www.suse.com/security/cve/CVE-2024-37020.html * https://www.suse.com/security/cve/CVE-2024-39355.html * https://bugzilla.suse.com/show_bug.cgi?id=1206418 * https://bugzilla.suse.com/show_bug.cgi?id=1211382 * https://bugzilla.suse.com/show_bug.cgi?id=1214099 * https://bugzilla.suse.com/show_bug.cgi?id=1215278 * https://bugzilla.suse.com/show_bug.cgi?id=1221323 * https://bugzilla.suse.com/show_bug.cgi?id=1224277 * https://bugzilla.suse.com/show_bug.cgi?id=1229129 * https://bugzilla.suse.com/show_bug.cgi?id=1230400 * https://bugzilla.suse.com/show_bug.cgi?id=1233313 * https://bugzilla.suse.com/show_bug.cgi?id=1237096 . Microcode_ctl update for SUSE fixes security issues, including potential DoS and escalation of privilege risks.. bsc#1206418, bsc#1211382, bsc#1214099, bsc#1215278, bsc#1221323, security, update, microcod. . Severity: Important. LinuxSecurity.com Team
An update that fixes 18 vulnerabilities is now available. . SUSE Security Update: Security update for kernel-firmware ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1065-1 Rating: important References: #1186938 #1188662 #1192953 #1195786 #1196333 Cross-References: CVE-2021-0066 CVE-2021-0071 CVE-2021-0072 CVE-2021-0076 CVE-2021-0161 CVE-2021-0164 CVE-2021-0165 CVE-2021-0166 CVE-2021-0168 CVE-2021-0170 CVE-2021-0172 CVE-2021-0173 CVE-2021-0174 CVE-2021-0175 CVE-2021-0176 CVE-2021-0183 CVE-2021-33139 CVE-2021-33155 CVSS scores: CVE-2021-0066 (NVD) : 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-0066 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-0071 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-0072 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0072 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0076 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-0076 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-0161 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0161 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0164 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-0164 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-0165 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0165 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0166 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0166 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0168 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0168 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0170 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0170 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0172 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0172 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0173 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0173 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0174 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0174 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0175 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0175 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0176 (NVD) : 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2021-0176 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2021-0183 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-0183 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-33139 (NVD) : 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-33139 (SUSE): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-33155 (NVD) : 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-33155 (SUSE): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High PerformanceComputing 15-SP3 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 ______________________________________________________________________________ An update that fixes 18 vulnerabilities is now available. Description: This update for kernel-firmware fixes the following issues: Update Intel Wireless firmware for 9xxx (INTEL-SA-00539, bsc#1196333): CVE-2021-0161: Improper input validation in firmware for Intel PROSet/Wireless Wi-Fi and Killer Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access. CVE-2021-0164: Improper access control in firmware for Intel PROSet/Wireless Wi-Fi and Killer Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access. CVE-2021-0165: Improper input validation in firmware for Intel PROSet/Wireless Wi-Fi and Killer Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0066: Improper input validation in firmware for Intel PROSet/Wireless Wi-Fi and Killer Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access. CVE-2021-0166: Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access. CVE-2021-0168: Improper input validation in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access. CVE-2021-0170: Exposure of Sensitive Information to an Unauthorized Actor in firmware for some IntelPROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow an authenticated user to potentially enable information disclosure via local access. CVE-2021-0172: Improper input validation in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0173: Improper Validation of Consistency within input in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0174: Improper Use of Validation Framework in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0175: Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0076: Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a privileged user to potentially enable denial of service via local access. CVE-2021-0176: Improper input validation in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a privileged user to potentially enable denial of service via local access. CVE-2021-0183: Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access. CVE-2021-0072: Improper input validation in firmware for some Intel PROSet/Wireless Wi-Fi and some Killer Wi-Fi may allow a privileged user to potentially enable information disclosure via local access. CVE-2021-0071: Improper inputvalidation in firmware for some Intel PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. Update Intel Bluetooth firmware (INTEL-SA-00604,bsc#1195786): - CVE-2021-33139: Improper conditions check in firmware for some Intel Wireless Bluetooth and Killer Bluetooth products before may allow an authenticated user to potentially enable denial of service via adjacent access. - CVE-2021-33155: Improper input validation in firmware for some Intel Wireless Bluetooth and Killer Bluetooth products before may allow an authenticated user to potentially enable denial of service via adjacent access. Bug fixes: - Updated the AMD SEV firmware (bsc#1186938) - Reduced the LZMA2 dictionary size (bsc#1188662) Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-1065=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-1065=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): kernel-firmware-20210208-150300.4.7.1 kernel-firmware-brcm-20210208-150300.4.7.1 ucode-amd-20210208-150300.4.7.1 - SUSE Linux Enterprise Micro 5.1 (noarch): kernel-firmware-all-20210208-150300.4.7.1 kernel-firmware-amdgpu-20210208-150300.4.7.1 kernel-firmware-ath10k-20210208-150300.4.7.1 kernel-firmware-ath11k-20210208-150300.4.7.1 kernel-firmware-atheros-20210208-150300.4.7.1 kernel-firmware-bluetooth-20210208-150300.4.7.1 kernel-firmware-bnx2-20210208-150300.4.7.1 kernel-firmware-brcm-20210208-150300.4.7.1 kernel-firmware-chelsio-20210208-150300.4.7.1 kernel-firmware-dpaa2-20210208-150300.4.7.1 kernel-firmware-i915-20210208-150300.4.7.1 kernel-firmware-intel-20210208-150300.4.7.1 kernel-firmware-iwlwifi-20210208-150300.4.7.1 kernel-firmware-liquidio-20210208-150300.4.7.1 kernel-firmware-marvell-20210208-150300.4.7.1 kernel-firmware-media-20210208-150300.4.7.1 kernel-firmware-mediatek-20210208-150300.4.7.1 kernel-firmware-mellanox-20210208-150300.4.7.1 kernel-firmware-mwifiex-20210208-150300.4.7.1 kernel-firmware-network-20210208-150300.4.7.1 kernel-firmware-nfp-20210208-150300.4.7.1 kernel-firmware-nvidia-20210208-150300.4.7.1 kernel-firmware-platform-20210208-150300.4.7.1 kernel-firmware-prestera-20210208-150300.4.7.1 kernel-firmware-qlogic-20210208-150300.4.7.1 kernel-firmware-radeon-20210208-150300.4.7.1 kernel-firmware-realtek-20210208-150300.4.7.1 kernel-firmware-serial-20210208-150300.4.7.1 kernel-firmware-sound-20210208-150300.4.7.1 kernel-firmware-ti-20210208-150300.4.7.1 kernel-firmware-ueagle-20210208-150300.4.7.1 kernel-firmware-usb-network-20210208-150300.4.7.1 ucode-amd-20210208-150300.4.7.1 References: https://www.suse.com/security/cve/CVE-2021-0066.html https://www.suse.com/security/cve/CVE-2021-0071.html https://www.suse.com/security/cve/CVE-2021-0072.html https://www.suse.com/security/cve/CVE-2021-0076.html https://www.suse.com/security/cve/CVE-2021-0161.html https://www.suse.com/security/cve/CVE-2021-0164.html https://www.suse.com/security/cve/CVE-2021-0165.html https://www.suse.com/security/cve/CVE-2021-0166.html https://www.suse.com/security/cve/CVE-2021-0168.html https://www.suse.com/security/cve/CVE-2021-0170.html https://www.suse.com/security/cve/CVE-2021-0172.html https://www.suse.com/security/cve/CVE-2021-0173.html https://www.suse.com/security/cve/CVE-2021-0174.html https://www.suse.com/security/cve/CVE-2021-0175.html https://www.suse.com/security/cve/CVE-2021-0176.html https://www.suse.com/security/cve/CVE-2021-0183.html https://www.suse.com/security/cve/CVE-2021-33139.html https://www.suse.com/security/cve/CVE-2021-33155.html https://bugzilla.suse.com/1186938 https://bugzilla.suse.com/1188662 https://bugzilla.suse.com/1192953 https://bugzilla.suse.com/1195786 https://bugzilla.suse.com/1196333 . SUSE has released a security update for the kernel-firmware that addresses 18 vulnerabilities, which encompass severe risk factors such as privilege escalation and denial of service concerns.. SUSE Security Update,kernel firmware threats,escalation of privilege,denial of service. . Severity: Important. LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for ucode-intel ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0576-1 Rating: important References: #1192615 #1195779 #1195780 #1195781 Cross-References: CVE-2021-0127 CVE-2021-0145 CVE-2021-0146 CVE-2021-33120 CVSS scores: CVE-2021-0127 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-0127 (SUSE): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-0145 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0145 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVE-2021-0146 (NVD) : 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-0146 (SUSE): 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVE-2021-33120 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L CVE-2021-33120 (SUSE): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for ucode-intel fixes the following issues: Updated to Intel CPU Microcode 20220207 release. - CVE-2021-0146: Fixed a potential security vulnerability in some Intel Processors may allow escalation of privilege (bsc#1192615) - CVE-2021-0127: Intel Processor Breakpoint Control Flow (bsc#1195779) - CVE-2021-0145: Fast store forward predictor - Cross Domain Training (bsc#1195780) - CVE-2021-33120: Out of bounds read for some Intel Atom processors (bsc#1195781) - Security updates for [INTEL-SA-00528](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html) - Security updates for [INTEL-SA-00532](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-576=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (x86_64): ucode-intel-20220207-3.38.1 ucode-intel-debuginfo-20220207-3.38.1 ucode-intel-debugsource-20220207-3.38.1 References: https://www.suse.com/security/cve/CVE-2021-0127.html https://www.suse.com/security/cve/CVE-2021-0145.html https://www.suse.com/security/cve/CVE-2021-0146.html https://www.suse.com/security/cve/CVE-2021-33120.html https://bugzilla.suse.com/1192615 https://bugzilla.suse.com/1195779 https://bugzilla.suse.com/1195780 https://bugzilla.suse.com/1195781 . The latest SUSE Linux update for ucode-intel addresses several critical vulnerabilities that pose risks to Intel CPUs.. Intel Security, SUSE Enterprise Update, Ucode Patch, Microcode Issues. . Severity: Important. LinuxSecurity.com Team
This update provides new and updated nonfree firmwares and fixes atleast the following security issues: Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable escalation of . MGASA-2022-0065 - Updated nonfree firmware packages fix security vulnerabilities Publication date: 15 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0065.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-0066, CVE-2021-0072, CVE-2021-0076, CVE-2021-0161, CVE-2021-0164, CVE-2021-0165, CVE-2021-0166, CVE-2021-0168, CVE-2021-0170, CVE-2021-0172, CVE-2021-0173, CVE-2021-0174, CVE-2021-0175, CVE-2021-0176, CVE-2021-33139, CVE-2021-33155 This update provides new and updated nonfree firmwares and fixes atleast the following security issues: Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access (CVE-2021-0066 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable information disclosure via local access (CVE-2021-0072 / SA-00539). Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable denial of service via local access (CVE-2021-0076 / SA-00539). Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access (CVE-2021-0161, CVE-2021-0168 / SA-00539). Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access (CVE-2021-0164 / SA-00539). Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentiallyenable denial of service via adjacent access (CVE-2021-0165 / SA-00539). Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access (CVE-2021-0166 / SA-00539). Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an authenticated user to potentially enable information disclosure via local access (CVE-2021-0170 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0172 / SA-00539). Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0173 / SA-00539). Improper Use of Validation Framework in firmware for some Intel(R) PROSet/ Wireless Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0174 / SA-00539). Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0175 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable denial of service via local access (CVE-2021-0176 / SA-00539). Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable denial of service via adjacent access (CVE-2021-33139 / SA-00604). Improper input validation in firmware for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable denial of service via adjacent access (CVE-2021-33155 / SA-00604). Full list offirmware changes/updates: * kernel-firmware-nonfree: - cnm: add chips&media wave521c firmware - cxgb4: Update firmware to revision 1.26.6.0 - i915: Add DMC firmware v2.16 for ADL-P - marvell: add CPT firmware images - mediatek: add firmware for MT7916 - mediatek: update firmware for MT7915 - mediatek: update firmware for MT7921 bluetooth chip - mediatek: update firmware for MT7921 WiFi device - mediatek: Update MT8173 VPU firmware to v1.1.7 - Mellanox: Add new mlxsw_spectrum firmware xx.2010.1232 - QCA: Add Bluetooth nvm file for WCN685x - QCA: Update Bluetooth WCN685x 2.0 firmware to 2.0.0-00609 - QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00324 - WHENCE: add missing symlink for NanoPi R1 * iwlwifi-firmware: - add new FWs from core63-136 release - add new FWs from core66-88 release - update 9000-family firmwares to core66-88 - Update firmware file for Intel Bluetooth 9260, 9462, 9560, AX200, AX201, AX210, AX211 * radeon-firmware: - amdgpu: update yellow carp dmcub firmware * rtlwifi-firmware: - rtw88: 8822c: Update normal firmware to v9.9.11 References: - https://bugs.mageia.org/show_bug.cgi?id=30038 - https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00539.html - https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00604.html - https://www.cve.org/CVERecord?id=CVE-2021-0066 - https://www.cve.org/CVERecord?id=CVE-2021-0072 - https://www.cve.org/CVERecord?id=CVE-2021-0076 - https://www.cve.org/CVERecord?id=CVE-2021-0161 - https://www.cve.org/CVERecord?id=CVE-2021-0164 - https://www.cve.org/CVERecord?id=CVE-2021-0165 - https://www.cve.org/CVERecord?id=CVE-2021-0166 - https://www.cve.org/CVERecord?id=CVE-2021-0168 - https://www.cve.org/CVERecord?id=CVE-2021-0170 - https://www.cve.org/CVERecord?id=CVE-2021-0172 - https://www.cve.org/CVERecord?id=CVE-2021-0173 - https://www.cve.org/CVERecord?id=CVE-2021-0174 - https://www.cve.org/CVERecord?id=CVE-2021-0175 - https://www.cve.org/CVERecord?id=CVE-2021-0176 -https://www.cve.org/CVERecord?id=CVE-2021-33139 - https://www.cve.org/CVERecord?id=CVE-2021-33155 SRPMS: - 8/nonfree/kernel-firmware-nonfree-20220209-1.mga8.nonfree - 8/nonfree/radeon-firmware-20220209-1.mga8.nonfree . Mageia 2022-0066 rolls out a new nonfree firmware patch that mitigates several vulnerabilities related to potential unauthorized data breaches.. Firmware Update, Mageia Security, Nonfree Firmware, Security Patch. . Severity: Important. LinuxSecurity.com Team
An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2021:2106-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2106 Issue date: 2021-05-25 CVE Names: CVE-2020-0466 CVE-2020-12362 CVE-2020-28374 CVE-2021-3347 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v. 8.1) - aarch64, ppc64le, x86_64 Red Hat Enterprise Linux BaseOS EUS (v. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466) * kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362) * kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374) * kernel: Use after free via PI futex state (CVE-2021-3347) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [Regression]RHEL8.2 - ISST-LTE:pVM:diapvmlp83:sum:memory DLPAR fails to add memory on multiple trials[mm/memory_hotplug.c:1163] (mm-) (BZ#1930170) * RHEL8.3 - Include patch: powerpc/pci: Remove LSI mappings on device teardown (xive/pci) (BZ#1931926) * [HPEMC 8.1 REGRESSION] skx_uncore: probe of 0008:80:08.0 failed with error -22 (BZ#1947115) * [Azure][RHEL-8]Mellanox Patches To Prevent Kernel Hang In MLX4 (BZ#1952072) * [HPEMC 8.4 REGRESSION]: perf/x86/intel/uncore kernel panic vulnerability on Haswell and Broadwell servers (BZ#1956686) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1899804 - CVE-2020-28374 kernel: SCSI target (LIO) write to any block on ILO backstore 1920480 - CVE-2020-0466 kernel: use after free in eventpoll.c may lead to escalation of privilege 1922249 - CVE-2021-3347 kernel: Use after free via PI futex state 1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.1): Source: kernel-4.18.0-147.48.1.el8_1.src.rpm aarch64: bpftool-4.18.0-147.48.1.el8_1.aarch64.rpm bpftool-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-core-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-cross-headers-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-core-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-devel-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-modules-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-modules-extra-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debuginfo-common-aarch64-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-devel-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-headers-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-modules-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-modules-extra-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-tools-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-tools-libs-4.18.0-147.48.1.el8_1.aarch64.rpm perf-4.18.0-147.48.1.el8_1.aarch64.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm python3-perf-4.18.0-147.48.1.el8_1.aarch64.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm noarch: kernel-abi-whitelists-4.18.0-147.48.1.el8_1.noarch.rpm kernel-doc-4.18.0-147.48.1.el8_1.noarch.rpm ppc64le: bpftool-4.18.0-147.48.1.el8_1.ppc64le.rpm bpftool-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-core-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-cross-headers-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-core-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-devel-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-modules-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-modules-extra-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debuginfo-common-ppc64le-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-devel-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-headers-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-modules-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-modules-extra-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-tools-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-tools-libs-4.18.0-147.48.1.el8_1.ppc64le.rpm perf-4.18.0-147.48.1.el8_1.ppc64le.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm python3-perf-4.18.0-147.48.1.el8_1.ppc64le.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm s390x: bpftool-4.18.0-147.48.1.el8_1.s390x.rpm bpftool-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm kernel-4.18.0-147.48.1.el8_1.s390x.rpm kernel-core-4.18.0-147.48.1.el8_1.s390x.rpm kernel-cross-headers-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-core-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-devel-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-modules-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debug-modules-extra-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm kernel-debuginfo-common-s390x-4.18.0-147.48.1.el8_1.s390x.rpm kernel-devel-4.18.0-147.48.1.el8_1.s390x.rpm kernel-headers-4.18.0-147.48.1.el8_1.s390x.rpm kernel-modules-4.18.0-147.48.1.el8_1.s390x.rpm kernel-modules-extra-4.18.0-147.48.1.el8_1.s390x.rpm kernel-tools-4.18.0-147.48.1.el8_1.s390x.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-core-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-devel-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-modules-4.18.0-147.48.1.el8_1.s390x.rpm kernel-zfcpdump-modules-extra-4.18.0-147.48.1.el8_1.s390x.rpm perf-4.18.0-147.48.1.el8_1.s390x.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm python3-perf-4.18.0-147.48.1.el8_1.s390x.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.s390x.rpm x86_64: bpftool-4.18.0-147.48.1.el8_1.x86_64.rpm bpftool-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-core-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-cross-headers-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-core-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-devel-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-modules-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-modules-extra-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debuginfo-common-x86_64-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-devel-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-headers-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-modules-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-modules-extra-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-tools-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-tools-libs-4.18.0-147.48.1.el8_1.x86_64.rpm perf-4.18.0-147.48.1.el8_1.x86_64.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm python3-perf-4.18.0-147.48.1.el8_1.x86_64.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v.8.1): aarch64: bpftool-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-debuginfo-common-aarch64-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm kernel-tools-libs-devel-4.18.0-147.48.1.el8_1.aarch64.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.aarch64.rpm ppc64le: bpftool-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-debuginfo-common-ppc64le-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm kernel-tools-libs-devel-4.18.0-147.48.1.el8_1.ppc64le.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.ppc64le.rpm x86_64: bpftool-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debug-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-debuginfo-common-x86_64-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-tools-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm kernel-tools-libs-devel-4.18.0-147.48.1.el8_1.x86_64.rpm perf-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm python3-perf-debuginfo-4.18.0-147.48.1.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-0466 https://access.redhat.com/security/cve/CVE-2020-12362 https://access.redhat.com/security/cve/CVE-2020-28374 https://access.redhat.com/security/cve/CVE-2021-3347 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYK0eI9zjgjWX9erEAQi19xAAlPo/dlGKDEIFAngimDRk7+eiyEXXfVGl 8OB2JcljeAvRsViaNUCYYygUKh4dd1FAxzJip8kc8VSzT5EgMmoyEWoSxRY8Ws+h jEiUHPEEO5sjsN4exTy/Zy7EoijOwMuCXJG3OaBfXus5VmGtMdJ3WA9z3X1VMYmR sXMuMW+iiICCDNXBNDkX3E6zdBLZRi2GbA0q0JxWy0P+7hN0817hUTCWE8vXrZHK 7FHjHiIQBi28axdqlBExsSo4dF/g+kZZeEwdYaeR9HY6i9MuNtsT7S02Pl6Z+owE zROQZi1fsZ15h6KWvWRi3mLibhLR6PX6fW+FvxjqBh1yLOMBXzPfDMXKklXq4GE5 mjN0pn8c/HaOObKrEYC57OSHnspIP/2Vsx773jUCb5HbLBCGuMq+apZlb/vb5yXj jH2znQTHYU/71PceNwt6LZCI11Q2jwB8KKUoqZMBbNiAdVkPIKc+OtXI9H5r7AKF 7pm/UKIcRvOMYy4412345wJolrJgEEvCL/YMF6F6tpbIzhtj6t2S3CIFZzxOYUKB 1F6chMh0CFe33XJKikWQoT0xfoZxGbbG1XZ0YiBJCvt2YrLMNL5ljX6dJS21igcU d6h4S8753nZmWsQCO1FGLahraLsggwry0i/VkBS+9D+thLylG/byHfm1fBqv993J F5OqAoLfQVo=zodN -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kpatch-patch security update Advisory ID: RHSA-2021:2099-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2099 Issue date: 2021-05-25 CVE Names: CVE-2020-0466 CVE-2020-28374 CVE-2021-3347 ==================================================================== 1. Summary: An update is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS EUS (v. 8.1) - ppc64le, x86_64 3. Description: This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Security Fix(es): * kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466) * kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374) * kernel: Use after free via PI futex state (CVE-2021-3347) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1899804 - CVE-2020-28374 kernel: SCSI target (LIO) write to any block on ILO backstore 1920480 - CVE-2020-0466 kernel: use after free in eventpoll.c may lead to escalation of privilege 1922249 - CVE-2021-3347 kernel: Use after free via PI futex state 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.1): Source: kpatch-patch-4_18_0-147_20_1-1-11.el8_1.src.rpm kpatch-patch-4_18_0-147_24_2-1-9.el8_1.src.rpm kpatch-patch-4_18_0-147_27_1-1-9.el8_1.src.rpm kpatch-patch-4_18_0-147_32_1-1-7.el8_1.src.rpm kpatch-patch-4_18_0-147_34_1-1-7.el8_1.src.rpm kpatch-patch-4_18_0-147_38_1-1-6.el8_1.src.rpm kpatch-patch-4_18_0-147_43_1-1-4.el8_1.src.rpm kpatch-patch-4_18_0-147_44_1-1-3.el8_1.src.rpm ppc64le: kpatch-patch-4_18_0-147_20_1-1-11.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_20_1-debuginfo-1-11.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_20_1-debugsource-1-11.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_24_2-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_24_2-debuginfo-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_24_2-debugsource-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_27_1-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_27_1-debuginfo-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_27_1-debugsource-1-9.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_32_1-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_32_1-debuginfo-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_32_1-debugsource-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_34_1-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_34_1-debuginfo-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_34_1-debugsource-1-7.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_38_1-1-6.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_38_1-debuginfo-1-6.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_38_1-debugsource-1-6.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_43_1-1-4.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_43_1-debuginfo-1-4.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_43_1-debugsource-1-4.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_44_1-1-3.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_44_1-debuginfo-1-3.el8_1.ppc64le.rpm kpatch-patch-4_18_0-147_44_1-debugsource-1-3.el8_1.ppc64le.rpm x86_64: kpatch-patch-4_18_0-147_20_1-1-11.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_20_1-debuginfo-1-11.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_20_1-debugsource-1-11.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_24_2-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_24_2-debuginfo-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_24_2-debugsource-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_27_1-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_27_1-debuginfo-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_27_1-debugsource-1-9.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_32_1-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_32_1-debuginfo-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_32_1-debugsource-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_34_1-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_34_1-debuginfo-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_34_1-debugsource-1-7.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_38_1-1-6.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_38_1-debuginfo-1-6.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_38_1-debugsource-1-6.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_43_1-1-4.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_43_1-debuginfo-1-4.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_43_1-debugsource-1-4.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_44_1-1-3.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_44_1-debuginfo-1-3.el8_1.x86_64.rpm kpatch-patch-4_18_0-147_44_1-debugsource-1-3.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-0466 https://access.redhat.com/security/cve/CVE-2020-28374 https://access.redhat.com/security/cve/CVE-2021-3347 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYKyc/9zjgjWX9erEAQibHw//a3LpsAtFlmzIJRMRXtLCkLlEkhjObDhS iKHvwlKSXixuP5YMYAXL/O5odoiLeXx3dC2aWpTcUrQJefH9ayVCYkQfJKWuDVru nbyfdTiZqf0+6x7Y3/xKUQ+pvYmSlIkUKE1Shrvh1KX2XklD+HcFcQEvgaQjjS1b GFFWE2ZvqFShyonEPWtX5gqm933d9X0qPJxNMqmBXsGwIznhfG7+F+SF3LB6lkH9 kOfJHdBNtaKV5gAOWD0yCp9EdQ/KwGeYRAJM2kvDhBK3IX64Qhc/ZoTpdffBh1PR nYvhDnPOysLudwx/KVLBEWhDGUeBmDAi7Y2KEDq4Gw5aHprkgdfLxEo4ZCFbZJAI ubbDBqxilS32P/sCTtfKQd0MEMgj/i3AWpspPsmMwcG9CERAhkBbAB8ngHKT3NY7 Vm5fuFaCMjqaefzSBlwyPZ6EiHH8hDafvMEDP2vkw0qLgqs0wBU2VLOPQmh4/rHY TvLSl/g77YQZzCreVO7ZgDiKHAwniQ47uxprIaWXLUhj762b/bK1xdyXx7X8flFj /slsXJnoY9dwhPfduAApgkVXhwJkmxJtsraoDjGW1KYc/FXuc1NbCsNsPgbM4RHX 7o6O+waCB5CCoZJ4JDX1uyOEBSxVG9Y2JHXMe+hi2/Ker/ETC4d2fayatUJgp1TY qRoPU27/meE=IgCq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2021:1081-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1081 Issue date: 2021-04-06 CVE Names: CVE-2020-0466 CVE-2020-27152 CVE-2020-28374 CVE-2021-3347 CVE-2021-26708 CVE-2021-27363 CVE-2021-27364 CVE-2021-27365 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Real Time (v. 8) - x86_64 Red Hat Enterprise Linux Real Time for NFV (v. 8) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466) * kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374) * kernel: Use after free via PI futex state (CVE-2021-3347) * kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708) * kernel: out-of-bounds read in libiscsi module (CVE-2021-27364) * kernel:heap buffer overflow in the iSCSI subsystem (CVE-2021-27365) * Kernel: KVM: host stack overflow due to lazy update IOAPIC (CVE-2020-27152) * kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt possible livelock: WARNING: CPU: 28 PID: 3109 at kernel/ptrace.c:242 ptrace_check_attach+0xdd/0x1a0 (BZ#1925308) * kernel-rt: update RT source tree to the RHEL-8.3.z3 source tree (BZ#1926369) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1888886 - CVE-2020-27152 Kernel: KVM: host stack overflow due to lazy update IOAPIC 1899804 - CVE-2020-28374 kernel: SCSI target (LIO) write to any block on ILO backstore 1920480 - CVE-2020-0466 kernel: use after free in eventpoll.c may lead to escalation of privilege 1922249 - CVE-2021-3347 kernel: Use after free via PI futex state 1925588 - CVE-2021-26708 kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c 1926369 - kernel-rt: update RT source tree to the RHEL-8.3.z3 source tree 1930078 - CVE-2021-27365 kernel: heap buffer overflow in the iSCSI subsystem 1930079 - CVE-2021-27363 kernel: iscsi: unrestricted access to sessions and handles 1930080 - CVE-2021-27364 kernel: out-of-bounds read in libiscsi module 6. Package List: Red Hat Enterprise Linux Real Time for NFV (v.8): Source: kernel-rt-4.18.0-240.22.1.rt7.77.el8_3.src.rpm x86_64: kernel-rt-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-core-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-core-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-devel-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-kvm-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-modules-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debuginfo-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-devel-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-kvm-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-modules-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-modules-extra-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm Red Hat Enterprise Linux Real Time (v. 8): Source: kernel-rt-4.18.0-240.22.1.rt7.77.el8_3.src.rpm x86_64: kernel-rt-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-core-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-core-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-devel-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-modules-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debuginfo-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-devel-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-modules-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm kernel-rt-modules-extra-4.18.0-240.22.1.rt7.77.el8_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-0466 https://access.redhat.com/security/cve/CVE-2020-27152 https://access.redhat.com/security/cve/CVE-2020-28374 https://access.redhat.com/security/cve/CVE-2021-3347 https://access.redhat.com/security/cve/CVE-2021-26708 https://access.redhat.com/security/cve/CVE-2021-27363 https://access.redhat.com/security/cve/CVE-2021-27364 https://access.redhat.com/security/cve/CVE-2021-27365 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYGxpNtzjgjWX9erEAQgpJg//W6iBKw5074KsHQzIOPiURc3w69o9gyIs yE7H0cLNIlUbfwMviXftPJzbPxAwasrqB7hQEcc9mqGFlxefWYCBBOSOkBn8wx9o +7bE6ZIKSEIN9rdHERsZdPMmP/kHbUmRgdo61jjZyQuUFfIZgjvJr8HkbeCEVzry TXqn4l5z230kRndXYO1hKIiWYCxMklKA0DY76CqPkAFMiLYf81TGY9cXdmvuBWkW TX42ufpPELH1E1z2x3DvsN4xK/wn6QPY3OYzEMk29C1LuKfylbXlGayL0eQNQAji UlE49OCvIeToqS4xCwlQTtOSDGtZkGX9WFpBXt8EGnJ/YDMRoxpxSYgqemqfDr+X XVhDcgXoAU5l+GJPD45dIWq7Gh/eAXZFV+jz4FtMU1oL2w+lR/eGCChEDG2GwTgl s9MhSz6BswbAWqdWYnAlzlcp/u7HsIku2a0puAJDpZO2TU1MPkitr3sHSc2XnCtg b8kbGtrS8QS9VckSGMAviuOZgpNDHKYTMGobyU5vnfgPPjhH3Z14CUoogGgVNvoA 3BdtyzVfB9uHhSSoRaLggUrOoPAxvlc5nfKGaFTyDkbVWmqOPdDPi7/Z6wJXwEkw vo6ExIPYJiAb05SuY+X0cJkCezokU8K5N0wFhj89t+BAbj5/IMiir2wwYGif4Hsb AAihwVSfz0U=X3VJ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.